Investigation of threats using queryable records of behavior
Abstract
Data of a digital communication account of a first user are parsed for one or more attributes of a series of digital activities including a first digital activity initially scored as non-malicious. Based on the parsed data, a searchable user communication digital profile is generated for the first user. The searchable user communication digital profile is searched based on a second digital activity and receiving a search result associated with the first digital activity. The first digital activity is rescored as malicious based on the search result. A security action associated with the rescored first digital activity is performed.
Claims
exact text as granted — not AI-modified1 . A system method comprising:
parsing data of a digital communication account of a first user for one or more attributes of a series of digital activities including a first digital activity initially scored as non-malicious; based on the parsed data, generating a searchable user communication digital profile for the first user;
searching the searchable user communication digital profile based on a second digital activity and receiving a search result associated with the first digital activity;
rescoring the first digital activity as malicious based on the search result; and
performing a security action associated with the rescored first digital activity.
2 . The method of claim 1 , wherein the digital communication account is an email account associated with a collaboration suite.
3 . The method of claim 1 , wherein the digital communication account is an account associated with a messaging platform.
4 . The method of claim 1 , wherein the one or more attributes include at least one of: a source Internet Protocol (IP) address, a time of transmission, a geographical origin, a sender identity, a recipient identity, content, or presence of an attachment.
5 . The method of claim 1 , wherein generating the searchable user communication digital profile comprises training a machine learning model based on past digital activities associated with the first user to establish normal behavior for the first user.
6 . The method of claim 1 , wherein the searchable user communication digital profile includes records for digital activities initially scored as safe and digital activities initially scored as unsafe.
7 . The method of claim 1 , wherein the second digital activity comprises a third digital activity performed using the digital communication account or another digital communication account associated with the first user or a second user.
8 . The method of claim 1 , wherein rescoring the first digital activity as malicious is further based on input received from a security operations center (SOC) analyst interacting with an interface displaying the search result.
9 . The method of claim 1 , wherein the security action comprises at least one of: quarantining the first digital activity, deleting the first digital activity, notifying an administrator, restricting access for the digital communication account, resetting a password for the digital communication account, or terminating active sessions for the digital communication account.
10 . The method of claim 1 , wherein parsing data comprises obtaining the data via an Application Programming Interface (API) associated with the digital communication account.
11 . The method of claim 1 , wherein the search result identifies the first digital activity based on sharing one or more attributes with the second digital activity.
12 . A system comprising:
a processor configured to:
parse data of a digital communication account of a first user for one or more attributes of a series of digital activities including a first digital activity initially scored as non-malicious;
based on the parsed data, generate a searchable user communication digital profile for the first user;
search the searchable user communication digital profile based on a second digital activity and receiving a search result associated with the first digital activity;
rescore the first digital activity as malicious based on the search result; and
perform a security action associated with the rescored first digital activity; and
a memory coupled to the processor and configured to provide the processor with instructions.
13 . The system of claim 12 , wherein the digital communication account is an account associated with a messaging platform or a collaboration suite.
14 . The system of claim 12 , wherein the one or more attributes include at least one of: a source Internet Protocol (IP) address, a time of transmission, a geographical origin, a sender identity, a recipient identity, content, or presence of an attachment.
15 . The system of claim 12 , wherein generating the searchable user communication digital profile comprises training a machine learning model based on past digital activities associated with the first user to establish normal behavior for the first user.
16 . The system of claim 12 , wherein the searchable user communication digital profile includes records for digital activities initially scored as safe and digital activities initially scored as unsafe.
17 . The system of claim 12 , wherein the second digital activity comprises a third digital activity performed using the digital communication account or another digital communication account associated with the first user or a second user.
18 . The system of claim 12 , wherein rescoring the first digital activity as malicious is further based on input received from a security operations center (SOC) analyst interacting with an interface displaying the search result.
19 . The system of claim 12 , wherein the security action comprises at least one of: quarantining the first digital activity, deleting the first digital activity, notifying an administrator, restricting access for the digital communication account, resetting a password for the digital communication account, or terminating active sessions for the digital communication account.
20 . A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:
parsing data of a digital communication account of a first user for one or more attributes of a series of digital activities including a first digital activity initially scored as non-malicious; based on the parsed data, generating a searchable user communication digital profile for the first user; searching the searchable user communication digital profile based on a second digital activity and receiving a search result associated with the first digital activity; rescoring the first digital activity as malicious based on the search result; and performing a security action associated with the rescored first digital activity.Join the waitlist — get patent alerts
Track US2025254190A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.